Kong / Kong/developer.konghq.com

Add an end-to-end Microsoft Entra ID + Kong OIDC App Registration guide

Open
#7,236 0 comments 0 reactions 0 assignees View on GitHub
user-reported
Dominant language
Ruby
Stars
28
Forks
121
Avg merge
1d 4h
Merged PRs (30d)
313

Description

## Jobs to be done (optional)
Customers using Kong Gateway's OpenID Connect (OIDC) plugin with Microsoft Entra ID need an end-to-end implementation guide that covers both the Microsoft Entra app registration/configuration and the corresponding Kong OIDC configuration.

The current Kong Azure AD OIDC example focuses primarily on the Kong OIDC plugin configuration and does not provide the detailed Microsoft Entra-side steps required to create and configure the application registrations.

For use cases where API developers access APIs through clients such as Postman, Python/Java applications, or CLI tools, customers may need multiple application registrations/client configurations. They need guidance on how these should be configured in Microsoft Entra ID and how the resulting values map to the Kong OIDC plugin configuration.

## Definition of done
Create a Kong-authored how-to guide covering an end-to-end Microsoft Entra ID + Kong OIDC implementation.

The documentation should provide an end-to-end flow so that a customer can follow the guide from Microsoft Entra application registration through to configuring and validating the Kong OIDC plugin.

## Information
Customer requested a Kong-specific end-to-end implementation guide for Microsoft Entra ID + Kong OIDC.
- Customer has already reviewed the existing Kong Azure AD OIDC example:
https://developer.konghq.com/plugins/openid-connect/examples/azure-ad/
- Existing Kong documentation primarily covers the Kong OIDC plugin configuration and does not provide detailed Microsoft Entra application registration steps specific to Kong.
- Microsoft documentation currently covers the generic Entra application registration process, but the customer is specifically requesting guidance on the Kong-specific configuration and mapping.

## Size
This requires a comprehensive how-to involving Kong OIDC and Microsoft Entra ID, including third-party application registration, permissions, scopes, redirect URIs, token/claim configuration, and multiple client use cases.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the existing Kong Azure AD OIDC example at developer.konghq.com/plugins/openid-connect/examples/azure-ad/ and review the Microsoft Entra application-registration steps needed alongside it. Done means a Kong-authored end-to-end guide covers registration, permissions, scopes, redirect URIs, token and claim configuration, mappings to the Kong OIDC plugin, validation, and multiple client use cases.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, documentation
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.